CVE-2023-29183
- EPSS 0.77%
- Veröffentlicht 13.09.2023 13:15:08
- Zuletzt bearbeitet 21.11.2024 07:56:40
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 and FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 ...
CVE-2023-33308
- EPSS 5.93%
- Veröffentlicht 26.07.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:05:23
A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary c...
CVE-2021-43072
- EPSS 0.05%
- Veröffentlicht 18.07.2023 03:15:54
- Zuletzt bearbeitet 21.11.2024 06:28:38
A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6.11 and below, FortiManager version 7.0...
CVE-2023-33306
- EPSS 0.2%
- Veröffentlicht 16.06.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 08:05:22
A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter.
CVE-2023-33307
- EPSS 0.07%
- Veröffentlicht 16.06.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 08:05:22
A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter.
CVE-2023-33305
- EPSS 0.14%
- Veröffentlicht 13.06.2023 09:15:18
- Zuletzt bearbeitet 21.11.2024 08:05:22
A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 th...
CVE-2023-29175
- EPSS 0.09%
- Veröffentlicht 13.06.2023 09:15:17
- Zuletzt bearbeitet 21.11.2024 07:56:39
An improper certificate validation vulnerability [CWE-295] in FortiOS 6.2 all versions, 6.4 all versions, 7.0.0 through 7.0.10, 7.2.0 and FortiProxy 1.2 all versions, 2.0 all versions, 7.0.0 through 7.0.9, 7.2.0 through 7.2.3 may allow a remote and u...
CVE-2023-29178
- EPSS 0.13%
- Veröffentlicht 13.06.2023 09:15:17
- Zuletzt bearbeitet 21.11.2024 07:56:39
A access of uninitialized pointer vulnerability [CWE-824] in Fortinet FortiProxy version 7.2.0 through 7.2.3 and before 7.0.9 and FortiOS version 7.2.0 through 7.2.4 and before 7.0.11 allows an authenticated attacker to repetitively crash the httpsd...
CVE-2022-43953
- EPSS 0.04%
- Veröffentlicht 13.06.2023 09:15:16
- Zuletzt bearbeitet 21.11.2024 07:27:24
A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS all versions 7.0, FortiOS all versions 6.4, FortiOS all versions 6.2, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7...
CVE-2023-22639
- EPSS 0.04%
- Veröffentlicht 13.06.2023 09:15:16
- Zuletzt bearbeitet 21.11.2024 07:45:06
A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy ...